There is an improper Neutralization of Special Elements used in an SQL Command (SQL Injection) vulnerability in php files of GESIO ERP. GESIO ERP all versions prior to 11.2 allows malicious users to retrieve all database information.
References
Link | Resource |
---|---|
https://www.incibe-cert.es/en/early-warning/security-advisories/gesio-sql-injection-vulnerability | Third Party Advisory |
Configurations
Information
Published : 2020-06-01 07:15
Updated : 2020-06-04 09:20
NVD link : CVE-2020-8967
Mitre link : CVE-2020-8967
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
gesio
- erp